CVE-2015-10062 MEDIUM

CVE-2015-10062: galaxy-data-resource Command Line Template injection

Vendor N/A
Product galaxy-data-resource
Weakness CWE-74
Published January 17, 2023
Last update August 6, 2024

CVSS base score

5.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to address this issue. The patch is named 50d65f45d3f5be5d1fbff2e45ac5cec075f07d42. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218451.

Key dates

02Disclosure timeline

January 17, 2023 CVE published
August 6, 2024 Record updated